This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
On 2024-05-15 at 03:05, Hans wrote:
Dear developers,
As usual, most of us here are not Debian developers, even if some of us
may be software developers.
in April 2024 the security hole CVE-2023-6546 was discovered in linux-image, and I believe, it
is fixed in kernel 6.1.0 (from debian/stable) as soon after this a new kernel was released.
However, there is no new kernel 6.5.0-*-bpo released at that time, so my question:
Does anyone know, if this fix was also integrated in kernel 6.5.0-*.bpo ?
I don't have a definitive answer, but you might look at:
https://security-tracker.debian.org/tracker/CVE-2023-6546
The only place it mentions 6.5 is in the Notes section, where it
mentions 6.5-rc7 (with a kernel.org link) in the context of a statement
that the Linux kernel in Debian buster does not include the vulnerable
code.
I would therefore suspect that any 6.5.x kernel probably was not
affected by this vulnerability to begin with.
--
The Wanderer
The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man. -- George Bernard Shaw
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEJCOqsZEc2qVC44pUBKk1jTQoMmsFAmZEly8ACgkQBKk1jTQo MmsP+w/9H9+hwKjrB9QHNmM9OFR6y4G7BYVbChDcp0karwySyvKdtvJNASPmlSKq /ykbFVZaQw6pLPDnPvB4on07oiWjaOjb0X+jO8IDcoCb2au40rQ5ZgJacalIe/1m qv7h/qOjqty1egfT4n/1Be6yhGHTGXvV92oSgboXsPLwKzoXQbdxjXSLBBzmuJH/ SAwG6QNTpz3Rxe6QBX9kyYdkN16umzwNJrQFLd4atcHgT56Add+GQP3mB3imKE9O FvncqIeB+pimIJs/DUBmQCcdLMcvP0Mhwimyi7Z6PweLjcbU/Al5XTF4YAJ76Dow n3IsgidbLinLg2JCdnBLKAIRVISKKsRMnjcv6VtaLeKOnFnf3GfK3Q6mHiaYbO5j QO9Fk8af4LLz+r6CHl4H1kwqcq7eJQDg1/wUa/xmTfDoYIhdv3bz3pF81LixgpV/ NQzBWKShg/4wUP0cRvQJiQnKYLkJ7NatJ2Jk1pSQgF/zqVUVGdCUwXjjObuyk+/H NEp49MxQR4Np/rBQIulERVdWpE4l/lS4IGG+kkjWkjP/tdcXE2E9pY3mP7mEVP1a hFRqaaHYOhfadJdvvnxErkVmvTKsm1/6Izn4rUqFWikyX9oLk0Scnh7gnexDUoX5 9FLe6OxY2qXmIpNUTtxF55/Yn/tO